Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,720
Quick preset (or use dates below)
Clear Filters
Showing 2,781 - 2,800 of 3,597 CVEs
CVE-2026-1435 CRITICAL - 9.8

Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued session identi...

Vendor: graylog
Product: graylog
Published: Feb 18, 2026
Source: NVD
CVE-2026-1937 CRITICAL - 9.8

The YayMail โ€“ WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the `yaymail_import_state` AJAX action in all versions up to, and including, 4.3.2. This makes it possible for...

Published: Feb 18, 2026
Source: NVD
CVE-2026-1670 CRITICAL - 9.8

The affected products are vulnerable to an unauthenticated API endpoint exposure, which may allow an attacker to remotely change the "forgot password" recovery email address.

Published: Feb 17, 2026
Source: NVD
CVE-2026-22769 CRITICAL - 10.0

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized acces...

Vendor: Dell
Product: RecoverPoint for Virtual Machines
Published: Feb 17, 2026
Source: NVD
CVE-2026-2630 CRITICAL - 9.9

A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted.

Published: Feb 17, 2026
Source: NVD
CVE-2026-26016 CRITICAL - 8.1

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers allows any user with access to a node secret token to fetch information about any server on a Pterodactyl instance, even...

Vendor: composer
Product: pterodactyl/panel
Published: Feb 17, 2026
Source: GitHub
CVE-2026-23647 CRITICAL - 9.8

Glory RBG-100 recycler systems using the ISPK-08 software component contain hard-coded operating system credentials that allow remote authentication to the underlying Linux system. Multiple local user accounts, including accounts with administrative privileges, were found to have fixed, embedded pas...

Vendor: Glory Global Solutions
Product: RBG-100
Published: Feb 17, 2026
Source: NVD
CVE-2025-70830 CRITICAL - 9.9

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to execute arbitrary code via injecting crafted Freemarker template syntax into the SQL script field.

Published: Feb 17, 2026
Source: NVD
CVE-2025-65753 CRITICAL - 9.0

An issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root.

Published: Feb 17, 2026
Source: NVD
CVE-2026-22208 CRITICAL - 9.6

OpenS100 (the reference implementation S-100 viewer) prior to commit 753cf29 contain a remote code execution vulnerability via an unrestricted Lua interpreter. The Portrayal Engine initializes Lua using luaL_openlibs() without sandboxing or capability restrictions, exposing standard libraries such a...

Vendor: OpenS100 Project
Product: OpenS100
Published: Feb 17, 2026
Source: NVD
CVE-2026-2439 CRITICAL - 9.8

Concierge::Sessions versions from 0.8.1 before 0.8.5 for Perl generate insecure session ids. The generate_session_id function in Concierge::Sessions::Base defaults to using the uuidgen command to generate a UUID, with a fallback to using Perl's built-in rand function. Neither of these methods a...

Published: Feb 16, 2026
Source: NVD
CVE-2025-15578 CRITICAL - 9.8

Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the system time (which is available from HTTP response headers), a call to the built-in rand() function, and the PID.

Vendor: TEEJAY
Product: Maypole
Published: Feb 16, 2026
Source: NVD
CVE-2025-65717 CRITICAL - 9.1

An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page.

Published: Feb 16, 2026
Source: NVD
CVE-2026-2577 CRITICAL - 10.0

The WhatsApp bridge component in Nanobot binds the WebSocket server to all network interfaces (0.0.0.0) on port 3001 by default and does not require authentication for incoming connections. An unauthenticated remote attacker with network access to the bridge can connect to the WebSocket server to hi...

Published: Feb 16, 2026
Source: NVD
CVE-2026-2550 CRITICAL - 9.8

A vulnerability was found in EFM iptime A6004MX 14.18.2. Affected is the function commit_vpncli_file_upload of the file /cgi/timepro.cgi. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was conta...

Published: Feb 16, 2026
Source: NVD
CVE-2026-26369 CRITICAL - 9.8

eNet SMART HOME server 2.2.1 and 2.3.1 contains a privilege escalation vulnerability due to insufficient authorization checks in the setUserGroup JSON-RPC method. A low-privileged user (UG_USER) can send a crafted POST request to /jsonrpc/management specifying their own username to elevate their acc...

Vendor: JUNG
Product: eNet SMART HOME server
Published: Feb 15, 2026
Source: NVD
CVE-2026-26366 CRITICAL - 9.8

eNet SMART HOME server 2.2.1 and 2.3.1 ships with default credentials (user:user, admin:admin) that remain active after installation and commissioning without enforcing a mandatory password change. Unauthenticated attackers can use these default credentials to gain administrative access to sensitive...

Vendor: JUNG
Product: eNet SMART HOME server
Published: Feb 15, 2026
Source: NVD
CVE-2025-32058 CRITICAL - 9.3

The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment over the INC interface through a custom protocol. There is a vulnerability during processing requests of this protocol on the V850 side which allows an attacker with code executio...

Vendor: Bosch
Product: Infotainment system ECU
Published: Feb 15, 2026
Source: NVD
CVE-2026-1490 CRITICAL - 9.8

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This m...

Published: Feb 15, 2026
Source: NVD
CVE-2025-8572 CRITICAL - 9.8

The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user registration. This makes it possible for unauthenticated attackers to create accounts with elevated ...

Published: Feb 14, 2026
Source: NVD